Ransomware Detection through Temporal Correlation between Encryption and I/O Behavior
Lihua Guo, Yiwei Hou, Chijin Zhou, Quan Zhang, Yu Jiang
摘要
In recent years, the increase in ransomware attacks has significantly impacted individuals and organizations. Many strategies have been proposed to detect ransomware's file disruption operation. However, they rely on certain assumptions that gradually fail in the face of evolving ransomware attacks, which use more stealthy encryption methods or benign-imitation-based I/O orchestration.
To mitigate this, we propose an approach to detect ransomware attacks through temporal correlation between encryption and I/O behaviors. Its key idea is that there is a strong temporal correlation inherent in ransomware's encryption and I/O behaviors. To disrupt files, ransomware must first read the file data from the disk into memory, encrypt it, and then write the encrypted data back to the disk. This process creates a pronounced temporal correlation between the computation load of the encryption operations and the size of the files being encrypted. Based on this invariant, we implement a prototype called RansomRadar and evaluate its effectiveness against 411 latest ransomware samples from 89 families. Experimental results show that it achieves a detection rate of 100.00% with 2.68% false alarms. Its F1-score is 96.03, higher than the existing detectors for 31.82 on average. CCS Concepts: • Security and privacy → Malware and its mitigation.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
它引用的顶会 Paper10
- Tracking Ransomware End-to-endDanny Yuxing Huang, Maxwell Matthaios Aliapoulios, Vector Guo Li, Luca Invernizzi 等S&P 2018 · 被引用 208 次
- FlashGuard: Leveraging Intrinsic Flash Properties to Defend Against Encryption RansomwareJian Huang, Jun Xu, Xinyu Xing, Peng Liu 等CCS 2017 · 被引用 94 次
- Don't Forget the I/O When Allocating Your LLCYifan Yuan, Mohammad Alian, Yipeng Wang, Ren Wang 等ISCA 2021 · 被引用 37 次
- RSSD: defend against ransomware with hardware-isolated network-storage codesign and post-attack analysisBenjamin Reidys, Peng Liu, Jian HuangASPLOS 2022 · 被引用 28 次
- Where's Crypto?: Automated Identification and Classification of Proprietary Cryptographic Primitives in Binary CodeCarlo Meijer, Veelasha Moonsamy, Jos WetzelsUSENIX Security 2021 · 被引用 26 次
相关 Paper
- ERW-Radar: An Adaptive Detection System against Evasive Ransomware by Contextual Behavior Detection and Fine-grained Content AnalysisLingbo Zhao, Yuhui Zhang, Zhilu Wang, Fengkai Yuan 等NDSS 2025
- UNVEIL: A Large-Scale, Automated Approach to Detecting RansomwareAmin Kharraz, Sajjad Arshad, Collin Mulliner, William K. Robertson 等USENIX Security 2016
- Detecting Ransomware Despite I/O Overhead: A Practical Multi-Staged ApproachChristian van Sloun, Vincent Woeste, Konrad Wolsing, Jan Pennekamp 等NDSS 2025
- An Empirical Study of Data Disruption by Ransomware AttacksYiwei Hou, Lihua Guo, Chijin Zhou, Yiwen Xu 等ICSE 2024 · 被引用 10 次
- Preventing Disruption of System Backup against Ransomware AttacksYiwei Hou, Lihua Guo, Chijin Zhou, Quan Zhang 等ISSTA 2025 · 被引用 1 次
